
Role-based administration and centralized policy management controlling access to credentials and privileged actions.

Role-based administration, including centralized policy management for controlling access to credentials and privileged actions, when applicable.
| Field | Response |
|---|---|
| Coverage | Console RBAC, ABAC/RBAC/Hybrid PAM policies, vault governance, in-session privileged action control |
| Approach | Two-layer model: administration RBAC + centralized Policy Center for credentials and privileged actions |
| Audit | Role assignments, policy changes, access decisions, vault ops, and command events logged tenant-scoped |
Layer 1 governs who configures the platform. Layer 2 governs who receives credentials and executes privileged actions on targets.
| Goal | Design Choice |
|---|---|
| Least-privilege admin | Atomic permissions (vault.read, access.approve) via roles |
| Central policy | Security Policy Center + PAM access policies - one surface |
| Consistent enforcement | Same engine for Standard, JIT, Emergency paths |
| Credential protection | Vault inject at session; reveal gated by vault.* permissions |
| Defense in depth | RequireRole + RequirePermission on every sensitive API |
| # | Reference | Path |
|---|---|---|
| 1 | Access control architecture | docs/guides/ACCESS_CONTROL_ARCHITECTURE.md |
| 2 | Role permission matrix | docs/guides/ROLE_PERMISSION_MATRIX.md |
| 3 | Authorization standards | docs/guides/AUTHORIZATION-STANDARDS.md |
| 4 | Security & policies (user guide) | docs/guides/user-guide/07-security-and-policies.md |
| 5 | Policy Center redesign | docs/implementation/POLICY-CENTER-REDESIGN-PLAN.md |

Code checks permissions, not role names. Custom roles are permission bundles - no redeploy required. JWT + /users/me returns flattened permissions[].
Admin RBAC configures users, policies, and vault. PAM Policy Center governs who connects and executes on resources - JIT, Standard, and Emergency paths share one policy engine. Code checks permissions, not role names.
| Layer | Question | Example |
|---|---|---|
| Admin RBAC | Who configures users, policies, vault? | Admin + security.policies.update publishes policy |
| PAM Policy | Who connects/executes on a resource? | JIT: DBA + prod tag + MFA + 4h + approver chain |
AccessControlPolicy model - RBAC, ABAC, or Hybrid.
Time · MFA · ticket · tags · network · intent scope.
Block · Allow · Alert on shell/RDP commands.
One policy definition. Every elevation path. Policies configured once govern Standard standing access, JIT elevation, and Emergency break-glass - with compliance framework linkage.

Approved request → policy evaluation → session launch → vault retrieves secret via service token → Zenx Gateway injects login. End users never receive plaintext passwords in normal connect flows.
| Vault Permission | Capability |
|---|---|
| vault.read | View metadata, rotation schedules, account linkage |
| vault.write | Update secrets, trigger rotation |
| vault.manage | Administrative vault operations (SecurityAdmin) |
| Access Permission | Privileged Action |
|---|---|
| access.request / access.create | Standard request · JIT elevation |
| access.approve / access.deny | Approve or deny pending requests |
| access.emergency | Break-glass (/emergency-access isolated route) |
| sessions.read / sessions.terminate | View · force-terminate live sessions |
| Task | Navigation | Min Permission |
|---|---|---|
| Manage roles | Identity → Roles | roles.read / roles.update |
| Edit access policies | Security → Policy Center | security.policies.update |
| Vault / rotation | Security → Rotation Workspace | vault.read / vault.write |
| Active sessions | Operations → Sessions | sessions.read / sessions.terminate |
| Emergency access | Access → Emergency | access.emergency |
| Control | Implementation |
|---|---|
| Backend authorization | [RequireRole] + [RequirePermission] on controllers |
| Tenant isolation | TenantIsolation via tenant_id JWT claim |
| Fail-closed | Missing permission → HTTP 403 |
| Workflow integration | Multi-level approval · ITSM ticket validation · audit chain |
| Compliance | SOC 2 · ISO 27001 · HIPAA · PCI-DSS policy evidence |